Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-hq85-3f6c-jx84

Опубликовано: 26 мар. 2026
Источник: github
Github: Не прошло ревью
CVSS3: 5.3

Описание

A flaw was found in p11-kit. A remote attacker could exploit this vulnerability by calling the C_DeriveKey function on a remote token with specific IBM kyber or IBM btc derive mechanism parameters set to NULL. This could lead to the RPC-client attempting to return an uninitialized value, potentially resulting in a NULL dereference or undefined behavior. This issue may cause an application level denial of service or other unpredictable system states.

A flaw was found in p11-kit. A remote attacker could exploit this vulnerability by calling the C_DeriveKey function on a remote token with specific IBM kyber or IBM btc derive mechanism parameters set to NULL. This could lead to the RPC-client attempting to return an uninitialized value, potentially resulting in a NULL dereference or undefined behavior. This issue may cause an application level denial of service or other unpredictable system states.

EPSS

Процентиль: 27%
0.00095
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-824

Связанные уязвимости

ubuntu
около 2 месяцев назад

[NULL dereference via C_DeriveKey with specific NULL parameters]

CVSS3: 5.3
redhat
около 2 месяцев назад

A flaw was found in p11-kit. A remote attacker could exploit this vulnerability by calling the C_DeriveKey function on a remote token with specific IBM kyber or IBM btc derive mechanism parameters set to NULL. This could lead to the RPC-client attempting to return an uninitialized value, potentially resulting in a NULL dereference or undefined behavior. This issue may cause an application level denial of service or other unpredictable system states.

debian

[NULL dereference via C_DeriveKey with specific NULL parameters]

EPSS

Процентиль: 27%
0.00095
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-824